CVE-2023-53213
published 2025-09-15CVE-2023-53213: In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: slab-out-of-bounds read in brcmf_get_assoc_ies() Fix a slab-out-of-bounds…
PriorityP430high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.15%
4.9th percentile
In the Linux kernel, the following vulnerability has been resolved:
wifi: brcmfmac: slab-out-of-bounds read in brcmf_get_assoc_ies()
Fix a slab-out-of-bounds read that occurs in kmemdup() called from
brcmf_get_assoc_ies().
The bug could occur when assoc_info->req_len, data from a URB provided
by a USB device, is bigger than the size of buffer which is defined as
WL_EXTRA_BUF_MAX.
Add the size check for req_len/resp_len of assoc_info.
Found by a modified version of syzkaller.
[ 46.592467][ T7] ==================================================================
[ 46.594687][ T7] BUG: KASAN: slab-out-of-bounds in kmemdup+0x3e/0x50
[ 46.596572][ T7] Read of size 3014656 at addr ffff888019442000 by task kworker/0:1/7
[ 46.598575][ T7]
[ 46.599157][ T7] CPU: 0 PID: 7 Comm: kworker/0:1 Tainted: G O 5.14.0+ #145
[ 46.601333][ T7] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.12.1-0-ga5cab58e9a3f-prebuilt.qemu.org 04/01/2014
[ 46.604360][ T7] Workqueue: events brcmf_fweh_event_worker
[ 46.605943][ T7] Call Trace:
[ 46.606584][ T7] dump_stack_lvl+0x8e/0xd1
[ 46.607446][ T7] print_address_description.constprop.0.cold+0x93/0x334
[ 46.608610][ T7] ? kmemdup+0x3e/0x50
[ 46.609341][ T7] kasan_report.cold+0x79/0xd5
[ 46.610151][ T7] ? kmemdup+0x3e/0x50
[ 46.610796][ T7] kasan_check_range+0x14e/0x1b0
[ 46.611691][ T7] memcpy+0x20/0x60
[ 46.612323][ T7] kmemdup+0x3e/0x50
[ 46.612987][ T7] brcmf_get_assoc_ies+0x967/0xf60
[ 46.613904][ T7] ? brcmf_notify_vif_event+0x3d0/0x3d0
[ 46.614831][ T7] ? lock_chain_count+0x20/0x20
[ 46.615683][ T7] ? mark_lock.part.0+0xfc/0x2770
[ 46.616552][ T7] ? lock_chain_count+0x20/0x20
[ 46.617409][ T7] ? mark_lock.part.0+0xfc/0x2770
[ 46.618244][ T7] ? lock_chain_count+0x20/0x20
[ 46.619024][ T7] brcmf_bss_connect_done.constprop.0+0x241/0x2e0
[ 46.620019][ T7] ? brcmf_parse_configure_security.isra.0+0x2a0/0x2a0
[ 46.620818][ T7] ? __lock_acquire+0x181f/0x5790
[ 46.621462][ T7] brcmf_notify_connect_status+0x448/0x1950
[ 46.622134][
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.27-1 (bookworm) | linux 6.1.27-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= cf2b448852abd47cee21007b8313fbf962bf3c9a < ac5305e5d227b9af3aae25fa83380d3ff0225b73 | ac5305e5d227b9af3aae25fa83380d3ff0225b73 |
| linux | linux | >= cf2b448852abd47cee21007b8313fbf962bf3c9a < 39f9bd880abac6068bedb24a4e16e7bd26bf92da | 39f9bd880abac6068bedb24a4e16e7bd26bf92da |
| linux | linux | >= cf2b448852abd47cee21007b8313fbf962bf3c9a < 425eea395f1f5ae349fb55f7fe51d833a5324bfe | 425eea395f1f5ae349fb55f7fe51d833a5324bfe |
| linux | linux | >= cf2b448852abd47cee21007b8313fbf962bf3c9a < 549825602e3e6449927ca1ea1a08fd89868439df | 549825602e3e6449927ca1ea1a08fd89868439df |
| linux | linux | >= cf2b448852abd47cee21007b8313fbf962bf3c9a < 936a23293bbb3332bdf4cdb9c1496e80cb0bc2c8 | 936a23293bbb3332bdf4cdb9c1496e80cb0bc2c8 |
| linux | linux | >= cf2b448852abd47cee21007b8313fbf962bf3c9a < e29661611e6e71027159a3140e818ef3b99f32dd | e29661611e6e71027159a3140e818ef3b99f32dd |
| linux | linux | >= cf2b448852abd47cee21007b8313fbf962bf3c9a < 228186629ea970cc78b7d7d5f593f2d32fddf9f6 | 228186629ea970cc78b7d7d5f593f2d32fddf9f6 |
| linux | linux | >= cf2b448852abd47cee21007b8313fbf962bf3c9a < 21bee3e649d87f78fe8aef6ae02edd3d6f310fd0 | 21bee3e649d87f78fe8aef6ae02edd3d6f310fd0 |
| linux | linux | >= cf2b448852abd47cee21007b8313fbf962bf3c9a < 0da40e018fd034d87c9460123fa7f897b69fdee7 | 0da40e018fd034d87c9460123fa7f897b69fdee7 |
| linux | linux_kernel | < 4.14.315 | 4.14.315 |
| linux | linux_kernel | >= 0 < 5.10.191-1 | 5.10.191-1 |
| linux | linux_kernel | >= 0 < 6.1.27-1 | 6.1.27-1 |
| linux | linux_kernel | >= 0 < 6.1.27-1 | 6.1.27-1 |
| linux | linux_kernel | >= 0 < 6.1.27-1 | 6.1.27-1 |
| linux | linux_kernel | >= 4.15 < 4.19.283 | 4.19.283 |
| linux | linux_kernel | >= 4.20 < 5.4.243 | 5.4.243 |
| linux | linux_kernel | >= 5.11 < 5.15.110 | 5.15.110 |
| linux | linux_kernel | >= 5.16 < 6.1.27 | 6.1.27 |
| linux | linux_kernel | >= 5.5 < 5.10.180 | 5.10.180 |
| linux | linux_kernel | >= 6.2 < 6.2.14 | 6.2.14 |
| linux | linux_kernel | >= 6.3 < 6.3.1 | 6.3.1 |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-53213: In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: slab-out-of-bounds read in brcmf_get_assoc_ies() Fix a slab-out-of
osv·2025-09-15·CVSS 7.1
CVE-2023-53213 [HIGH] CVE-2023-53213: In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: slab-out-of-bounds read in brcmf_get_assoc_ies() Fix a slab-out-of
In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: slab-out-of-bounds read in brcmf_get_assoc_ies() Fix a slab-out-of-bounds read that occurs in kmemdup() called from brcmf_get_assoc_ies(). The bug could occur when assoc_info->req_len, data from a URB provided by a USB device, is bigger than the size of buffer which is defined as WL_EXTRA_BUF_MAX. Add the size check for req_len/resp_len of assoc_info. Found by a modified version of syzkaller. [ 46.592467][ T7] ================================================================== [ 46.594687][ T7] BUG: KASAN: slab-out-of-bounds in kmemdup+0x3e/0x50 [ 46.596572][ T7] Read of size 3014656 at addr ffff888019442000 by task kworker/0:1/7 [ 46.598575][ T7] [ 46.599157][ T7] CPU: 0 PID: 7 Comm: kworker/0:1 Tainted: G
GHSA
GHSA-fq2q-2mv8-c2mg: In the Linux kernel, the following vulnerability has been resolved:
wifi: brcmfmac: slab-out-of-bounds read in brcmf_get_assoc_ies()
Fix a slab-out-
ghsa_unreviewed·2025-09-15
CVE-2023-53213 [HIGH] CWE-125 GHSA-fq2q-2mv8-c2mg: In the Linux kernel, the following vulnerability has been resolved:
wifi: brcmfmac: slab-out-of-bounds read in brcmf_get_assoc_ies()
Fix a slab-out-
In the Linux kernel, the following vulnerability has been resolved:
wifi: brcmfmac: slab-out-of-bounds read in brcmf_get_assoc_ies()
Fix a slab-out-of-bounds read that occurs in kmemdup() called from
brcmf_get_assoc_ies().
The bug could occur when assoc_info->req_len, data from a URB provided
by a USB device, is bigger than the size of buffer which is defined as
WL_EXTRA_BUF_MAX.
Add the size check for req_len/resp_len of assoc_info.
Found by a modified version of syzkaller.
[ 46.592467][ T7] ==================================================================
[ 46.594687][ T7] BUG: KASAN: slab-out-of-bounds in kmemdup+0x3e/0x50
[ 46.596572][ T7] Read of size 3014656 at addr ffff888019442000 by task kworker/0:1/7
[ 46.598575][ T7]
[ 46.599157][ T7] CPU: 0 PID: 7 Comm: kworker/0:1 Tainte
Red Hat
kernel: wifi: brcmfmac: slab-out-of-bounds read in brcmf_get_assoc_ies()
vendor_redhat·2025-09-15·CVSS 7.1
CVE-2023-53213 [HIGH] CWE-125 kernel: wifi: brcmfmac: slab-out-of-bounds read in brcmf_get_assoc_ies()
kernel: wifi: brcmfmac: slab-out-of-bounds read in brcmf_get_assoc_ies()
In the Linux kernel, the following vulnerability has been resolved:
wifi: brcmfmac: slab-out-of-bounds read in brcmf_get_assoc_ies()
Fix a slab-out-of-bounds read that occurs in kmemdup() called from
brcmf_get_assoc_ies().
The bug could occur when assoc_info->req_len, data from a URB provided
by a USB device, is bigger than the size of buffer which is defined as
WL_EXTRA_BUF_MAX.
Add the size check for req_len/resp_len of assoc_info.
Found by a modified version of syzkaller.
[ 46.592467][ T7] ==================================================================
[ 46.594687][ T7] BUG: KASAN: slab-out-of-bounds in kmemdup+0x3e/0x50
[ 46.596572][ T7] Read of size 3014656 at addr ffff888019442000 by task kworker/0:1/7
[ 46.
Debian
CVE-2023-53213: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: brcmf...
vendor_debian·2023·CVSS 7.1
CVE-2023-53213 [HIGH] CVE-2023-53213: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: brcmf...
In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: slab-out-of-bounds read in brcmf_get_assoc_ies() Fix a slab-out-of-bounds read that occurs in kmemdup() called from brcmf_get_assoc_ies(). The bug could occur when assoc_info->req_len, data from a URB provided by a USB device, is bigger than the size of buffer which is defined as WL_EXTRA_BUF_MAX. Add the size check for req_len/resp_len of assoc_info. Found by a modified version of syzkaller. [ 46.592467][ T7] ================================================================== [ 46.594687][ T7] BUG: KASAN: slab-out-of-bounds in kmemdup+0x3e/0x50 [ 46.596572][ T7] Read of size 3014656 at addr ffff888019442000 by task kworker/0:1/7 [ 46.598575][ T7] [ 46.599157][ T7] CPU: 0 PID: 7 Comm: kworker/0:1 Tainted: G
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/0da40e018fd034d87c9460123fa7f897b69fdee7https://git.kernel.org/stable/c/21bee3e649d87f78fe8aef6ae02edd3d6f310fd0https://git.kernel.org/stable/c/228186629ea970cc78b7d7d5f593f2d32fddf9f6https://git.kernel.org/stable/c/39f9bd880abac6068bedb24a4e16e7bd26bf92dahttps://git.kernel.org/stable/c/425eea395f1f5ae349fb55f7fe51d833a5324bfehttps://git.kernel.org/stable/c/549825602e3e6449927ca1ea1a08fd89868439dfhttps://git.kernel.org/stable/c/936a23293bbb3332bdf4cdb9c1496e80cb0bc2c8https://git.kernel.org/stable/c/ac5305e5d227b9af3aae25fa83380d3ff0225b73https://git.kernel.org/stable/c/e29661611e6e71027159a3140e818ef3b99f32dd
2025-09-15
Published